CVE-2021-37695

Description

ckeditor is an open source WYSIWYG HTML editor with rich content support. A potential vulnerability has been discovered in CKEditor 4 [Fake Objects](https://ckeditor.com/cke4/addon/fakeobjects) package. The vulnerability allowed to inject malformed Fake Objects HTML, which could result in executing JavaScript code. It affects all users using the CKEditor 4 plugins listed above at version < 4.16.2. The problem has been recognized and patched. The fix will be available in version 4.16.2.

Risk Information

Base Score
5.4
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
EPSS Score
Exploitation Probability
0.74

Associated Vulnerability

VulnerabilityOS Platform
Multiple Vulnerabilities are affected in IBM Sterling B2B Integrator 6.1.2.5Windows
Multiple vulnerabilities are affected in Oracle PeopleSoft Enterprise PeopleTools 8.57Windows
Multiple vulnerabilities are affected in Oracle PeopleSoft Enterprise PeopleTools 8.58Windows
Multiple vulnerabilities are affected in Oracle PeopleSoft Enterprise PeopleTools 8.59Windows
Multiple Vulnerabilities are affected in IBM Sterling B2B Integrator 6.2.0.2Windows
text editor which can be embedded into web pages (USN-5340-1) ckeditor_4.12.1+dfsg-1ubuntu0.1_all.debLinux
text editor which can be embedded into web pages (USN-5340-1) ckeditor_4.16.0+dfsg-2ubuntu0.1_all.debLinux
text editor which can be embedded into web pages (USN-5340-1) ckeditor_4.5.7+dfsg-2ubuntu0.18.04.1_all.debLinux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234